External Script Fetching
- Category
- Supply Chain
- Confidence
- 93% confidence
- Finding
The skill instructs the agent to install software by piping a remotely fetched script directly into a shell (
curl ... | bash). This is dangerous because it executes unverified code from the network with the user's privileges, enabling supply-chain compromise, MITM-related execution in weaker trust environments, or malicious changes on the hosting server to become instant code execution.- Content
-
oo: command not found— install the oo CLI (other platforms: https://cli.oomol.com/install-guide.md):bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linuxpowershell
-
